Security at SprintGraph
SprintGraph is designed around a simple privacy principle: your research dataset should not need to be uploaded to SprintGraph in order to create a figure.
During the ordinary figure-building workflow, research datasets you enter, paste, or import into SprintGraph are processed locally in your browser and are not uploaded to or stored on SprintGraph servers as part of that workflow.
That architecture reduces the amount of research data SprintGraph receives in the first place.
Your research dataset is processed in your browser
SprintGraph processes the tabular research datasets you use for figure creation locally in your browser.
This includes supported CSV, TSV, and TXT data used in the workspace.
SprintGraph's analytics are configured so that they do not receive the contents of your raw research datasets or the contents of your locally saved SprintGraph projects.
SprintGraph does not use behavioral-advertising technology or session replay inside the figure-building workspace.
SprintGraph also does not use generative AI to invent, alter, or interpret your research results as part of its figure-building functionality.
Projects are saved locally
Supported SprintGraph projects are saved locally in your browser using browser storage, including IndexedDB.
SprintGraph does not upload those locally saved projects to its servers as part of the ordinary project-saving process.
This means SprintGraph ordinarily does not maintain a cloud copy that it can view, recover, or remotely delete.
It also means the security and persistence of those projects depend in part on your own browser and device.
Clearing browser data, resetting your browser, changing devices, using software that removes browser storage, or losing access to your device may result in locally saved projects being lost. Because SprintGraph may not possess a server copy, we may be unable to restore a project that has been deleted from your local browser storage.
For important work, maintain appropriate copies using SprintGraph's available project-export functionality.
Your research dataset is separate from account information
Local dataset processing does not mean SprintGraph receives no information when you use the service.
SprintGraph separately handles information necessary to operate the service and our business. Depending on how you use SprintGraph, this can include account and authentication information, subscription status, transaction information, communications with SprintGraph, feedback or form submissions, analytics or product-usage information, and limited technical or service information.
That information is separate from the research datasets you use in the normal figure-building workflow.
For example, becoming a SprintGraph Pro subscriber requires SprintGraph and its payment provider to process information about your subscription and payment. It does not require SprintGraph to receive the research dataset you are using to build a figure.
Likewise, SprintGraph may use analytics to understand product usage, but those analytics do not receive the raw contents of your research dataset or locally saved SprintGraph projects.
For more detail about the information SprintGraph receives and how it is used, please see our Privacy Policy.
Payments and service providers
SprintGraph relies on specialized third-party providers for functions needed to operate the service, including payments, account and application infrastructure, communications, analytics, and technical infrastructure.
SprintGraph uses Stripe for payment and subscription processing.
Using an outside provider for one of these functions does not change the ordinary local-processing model for research datasets in the SprintGraph workspace. Research datasets are not sent to a payment provider merely because you subscribe to SprintGraph Pro.
The providers SprintGraph uses may change as the service evolves. Material changes in how SprintGraph handles personal information will be reflected in our privacy disclosures where appropriate.
Sensitive and regulated research
SprintGraph's local-processing architecture can be useful when researchers want to minimize transmission of their underlying datasets.
However, the standard SprintGraph Services are not offered as HIPAA-compliant services.
You must not use SprintGraph in a manner that requires SprintGraph to act as a HIPAA business associate unless SprintGraph has separately entered into an appropriate written agreement governing that use.
If you work with health information, confidential research information, or other regulated or sensitive data, you are responsible for determining whether your use of SprintGraph is permitted by the laws, institutional requirements, research protocols, data-use agreements, consent requirements, contracts, or other obligations that apply to your work.
There is an important difference between using a research dataset locally in the SprintGraph workspace and intentionally sending information to SprintGraph.
Do not send protected health information or similarly highly regulated research information to SprintGraph through support, feedback forms, email, or other SprintGraph-controlled communications unless SprintGraph has entered into a separate written agreement expressly authorizing and governing SprintGraph's receipt of that information.
When possible, use a redacted or synthetic example when requesting support involving sensitive research.
Your device is part of the security model
Because SprintGraph processes research datasets and stores supported projects locally, the security of your own device and browser matters.
Use safeguards appropriate to the sensitivity of your work, including maintaining control of your device, protecting your operating-system and browser accounts, keeping software reasonably current, and using appropriate device security.
If you use SprintGraph on a shared, managed, public, or institutionally controlled computer, remember that locally stored information may be accessible to or affected by other users, administrators, browser settings, or device-management policies.
SprintGraph's local-processing design reduces the research information SprintGraph possesses. It does not replace security controls that may be required for your own device, institution, laboratory, organization, or research environment.
What SprintGraph does not claim
We believe security information should be specific and supportable.
SprintGraph does not claim certification or compliance with standards merely because those standards are commonly associated with software companies.
Unless SprintGraph expressly states otherwise based on a verified program or assessment, you should not interpret this page as representing that SprintGraph is SOC 2 certified, ISO 27001 certified, HIPAA compliant, or certified under another security or regulatory framework.
SprintGraph also does not claim that any website, browser, device, network, or software system can be guaranteed to be completely secure.
Our goal is to describe SprintGraph's actual architecture and practices accurately rather than make security claims we cannot substantiate.
Reporting a security concern
If you believe you have discovered a security vulnerability, account-security issue, or other security concern involving SprintGraph, contact:
Please provide enough information for us to understand and investigate the issue, but do not send protected health information, raw sensitive research datasets, passwords, payment-card numbers, or other unnecessary sensitive information in your report.
We appreciate responsible reports that help us protect SprintGraph and its users.
